Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33810

Опубликовано: 08 апр. 2026
Источник: debian
EPSS Низкий

Описание

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.2-1package
golang-1.25not-affectedpackage
golang-1.24not-affectedpackage
golang-1.19not-affectedpackage
golang-1.15not-affectedpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU

  • https://github.com/golang/go/issues/78332

  • Fixed by: https://github.com/golang/go/commit/ceb4da6626ce94d75b2aefd0f24c6d0fd74f45f9 (go1.26.2)

EPSS

Процентиль: 17%
0.00262
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.8
redhat
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
nvd
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 5.9
msrc
3 месяца назад

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 7.5
github
3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

EPSS

Процентиль: 17%
0.00262
Низкий